Four federal cyber officials shared Black Hat's main stage on August 4, something the conference has never done in this configuration. They treated the hour as one argument about who does what when an attack hits, and who is still around five years from now to keep doing it.
The Lineup Nobody Had Seen Before
National Cyber Director Sean Cairncross opened with a fireside conversation alongside Misha Laskin, CEO of Reflection AI, with Black Hat's opening host, Suzy Pallett, setting up the session. The stage then reset for a panel titled "Disruption, Defense and Operational Readiness," moderated by Daniel Kroese, Vice President of Global Policy at Palo Alto Networks, with Nick Andersen, CISA's acting director, Brett Leatherman, assistant director of the FBI's Cyber Division, and Katherine "Katie" E. Sutton, Assistant Secretary of War for Cyber Policy and principal cyber advisor to the Secretary of War.
That title, Department of War rather than Defense, marks how much has shifted since Black Hat last put a sitting national cyber director on this stage. The panel's stated focus was disruption operations against attacker infrastructure, critical infrastructure defense, and folding cyber capability into conventional military planning. An $18.1 million office doesn't run a hobby project at that scale.
Open Source as Default, Not Exception
The fireside conversation's clearest policy signal came early. Cairncross argued that open source should stop sitting behind commercial software as the fallback choice and start as the preferred one, both in the United States and in how the country exports its technology stance globally. His reasoning: an ecosystem where developers hold real influence over direction produces innovation. One managed top-down by a vendor roadmap doesn't.
That framing lines up with what Cairncross told CyberScoop days earlier about the administration's AI executive order: a regulatory regime would go obsolete before it cleared review, so the preferred lever is building competitive U.S. open source technology and pairing it with faster information sharing between industry and government. The Black Hat remarks weren't a new position. They were the same position, delivered to the audience that has to operationalize it.
What the Panel Added
Disrupting a ransomware crew's infrastructure and coordinating a 2 a.m. critical infrastructure response takes people, not a stated preference for open source. That's the gap the panel addressed.
Andersen and Leatherman described a risk-based approach to prioritizing which infrastructure gets protection, paired with disruption operations that go after attacker servers, funding, and tooling at the same time rather than one after another. Sutton added the military piece: folding cyber capability directly into conventional operations planning at the Department of War. Kroese, moderating from the private sector rather than presenting on behalf of it, kept the panel on operational specifics instead of policy generalities.
Cairncross had already put the connective tissue in plain terms during the fireside chat, paraphrased here rather than quoted verbatim: security has to be a collaboration. The United States will keep leading on open source while getting stricter about protecting the infrastructure and people that make it work. Cyber is a specialized profession. Losing continuity of expertise between government and the private sector means losing the fight before it starts.
The Workforce Problem Underneath the Policy
That last point is the one worth sitting with.
Open source policy and disruption operations are visible, announceable wins. Workforce continuity isn't. It shows up as attrition data nobody presents from a keynote stage.
A national cyber director's office marked at $18.1 million for FY2026, below its own $20 million request and headed toward roughly $17 million in the FY2027 proposal, can't train or retain the specialists this strategy depends on. That capacity sits inside CISA, the FBI's Cyber Division, the Department of War, and the private sector security teams that increasingly compete with government pay scales for the same people. The information-sharing structure Cairncross described in his CyberScoop remarks, flexible enough to move fast, secure enough to trust, is only as good as the people staffing both sides of it long enough to build that trust in the first place.
If the federal government is preferentially adopting open source and building faster public-private information sharing, what does your organization's side of that channel look like today: a named contact at CISA or your sector's ISAC, or a policy binder nobody has opened since the last audit?
I sat in the front row for this fireside chat as part of Black Hat USA 2026 coverage. More from the show follows this week.
Black Hat. "Black Hat USA 2026 Keynotes to Address AI's Impact on Cyber Operations, Defense Strategy, and Vulnerability Research." July 16, 2026.
CyberScoop. "National Cyber Director Lays Out White House Plans to Secure AI Without Writing New Rules." August 2026.
ExecutiveGov. "House Advances FY2026 Spending Bill." September 9, 2025.
CyberScoop. "Trump Budget Proposal Would Slash More Than 1,000 CISA Jobs." June 2025.
CSO Online. "The Cyber Winners and Losers in Trump's 2027 Budget." April 10, 2026.
